Packet Profiling via Risk Scoring and Quarantine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for data packet inspection and delivery lack comprehensive profiling and risk assessment, failing to effectively identify and manage malicious or suspicious data packets before they enter organizational networks, which can lead to security breaches.

Innovation Solution

A method and system for packet profiling that involves a transport provider analyzing incoming data packets using inspection sentinels and scoring modules to mark and route packets based on risk, with the option to quarantine suspicious packets for further analysis, and providing feedback mechanisms to improve assessment procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive packet inspection and analysis is performed to identify malicious data packets, then network security is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The transport provider performs preliminary packet profiling, analysis, and risk scoring before packets reach the organization's network. Inspection sentinels and scoring modules evaluate packets in advance, marking them with risk levels so that downstream systems only need to make simple routing decisions based on pre-computed scores, rather than performing comprehensive analysis on every packet

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The packet inspection system is divided into multiple independent components: transport provider profiling systems, organization verification systems, inspection sentinels, and scoring modules. Each component performs a specific function in the inspection chain, allowing parallel processing and distributing the computational burden across multiple specialized systems rather than one monolithic processor

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If multiple inspection sentinels and scoring modules are deployed to accurately profile packets, then detection precision is improved, but device complexity increases

Engineering Contradiction:
Improvepacket risk assessment accuracyVSAvoidinspection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The packet profiling system uses universal data structures and standardized assessment procedures that can be applied across multiple organizations and transport providers. The scoring modules and inspection sentinels use common protocols and data formats, allowing the same infrastructure to serve multiple customers without requiring separate complex systems for each organization

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The transport provider acts as an intermediary that performs the complex packet analysis and profiling work, using inspection sentinels and scoring modules to evaluate packets before they reach the organization. This intermediary approach allows organizations to benefit from sophisticated inspection capabilities without having to deploy and maintain the complex inspection infrastructure themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If suspicious packets are quarantined for further analysis, then security reliability is improved, but processing time increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidquarantine processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Suspicious packets are extracted and removed from the main data flow and placed in quarantine zones for further analysis. This separation allows the primary data transmission channel to continue operating at normal speed while suspicious packets undergo additional verification, preventing security analysis from becoming a bottleneck for overall system throughput

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system automatically routes packets to appropriate handling based on their risk scores without requiring manual intervention. Low-risk packets are automatically delivered, medium-risk packets are automatically quarantined for further analysis, and high-risk packets are automatically blocked. This automated decision-making reduces the time overhead associated with security processing by eliminating manual review steps

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9106684B1System and method for packet profiling
Publication Date: 2015.08.11 JPMORGAN CHASE BANK NA
  • US9106684B1 patent drawing
  • US9106684B1 patent drawing
  • US9106684B1 patent drawing

AI summary

Systems and methods for packet profiling are disclosed. According to one embodiment, a method for profiling incoming data packets for an organization includes the steps of (1) receiving, at an interface for a transport provider, a data packet; (2) using a computer processor, analyzing the data packet; (3) using the computer processor, based on the analysis, marking the data packet; and (4) transmitting the data packet to the organization.